CVE-2026-73570
Exploited in the wild. In CISA KEV since 2026‑08‑21. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your Zimbra server is running Collaboration (ZCS) older than 10.1.20, and whether the optional zimbra-snmp package is installed.
- Verify whether SNMP notifications are enabled in your Zimbra/SNMP configuration.
- If both are true, plan to upgrade Collaboration to fixed version 10.1.20 (or later) using Zimbra’s official security guidance.
- If you cannot upgrade immediately, disable SNMP notifications and/or remove the zimbra-snmp package per vendor instructions, then confirm the change took effect.
- Document the date/time of the change and monitor for suspicious activity on the Zimbra host until the update is completed.
What it is
From the CVE record
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
In plain language
Written by AI from the recordIf you run Zimbra Collaboration and have the optional zimbra-snmp package installed with SNMP notifications turned on, you should treat CVE-2026-73570 as an urgent remote takeover risk and update to 10.1.20 or later immediately.
CVE-2026-73570 is a remote code execution flaw in Zimbra Collaboration via SNMP notification processing: improper sanitization of untrusted input can let an unauthenticated attacker trigger arbitrary OS command execution as the Zimbra user when zimbra-snmp is installed and SNMP notifications are enabled; it is listed in CISA KEV with an action deadline of 2026-08-24.
If you're affected
- Full server takeover
- Malware installation risk
- Customer email data compromise
- Service outage and disruption
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-08-21.
US federal agencies must remediate by 2026-08-24.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
12% chance of exploitation activity in the next 30 days, which ranks it in the 96th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
18 events over 35 days, from the signal feeds we watch.
- EPSS band change0 → moderateepss band change
- Nuclei check added
- Analysis publishedZimbra's Optional SNMP Package Turned Into an Unauthenticated RCE — and CERT Polska Caught It Exploitedpatch available, record updated
- Patch availablerecord updated
- Added to CISA KEVpatch available, record updated, record updated
- Record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Scored 8.9 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope ChangedThe exploit can affect other components (e.g. sandbox escape, host compromise from VM)
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability LowReduced performance or intermittent disruption of service
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- wiki.zimbra.com/wiki/Zimbra_Security_Advisories
- wiki.zimbra.com/wiki/Security_Center
- moje.cert.pl/komunikaty/2026/145/aktywnie-wykorzystywana-podatnosc-w-zimbra-collaboration-suite/
And 1 more reference. See all after sign-in
In the news
- Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited
- Hackers breached over 270 Zimbra servers in ongoing attacks
- Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
- Exploited Zimbra Flaw Highlights Shrinking Window to Patch
- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
- CISA orders urgent patching of actively exploited Zimbra flaw
- Hackers Target Zimbra Servers in Active Exploitation Campaign
- Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
- Critical Zimbra RCE flaw now actively exploited in attacks
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Collaboration, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI